Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ“Š Monitoring
  3. Obsidian MCP Secure
Obsidian MCP Secure logo
Health: ActiveRecent health check succeeded.Last checked 9/7/2026, 7:35:04 PM

Obsidian MCP Secure

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View RepositoryVisit Website

Secure MCP server for Obsidian with OWASP Top 10 controls and full audit logging.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "obsidian-mcp-secure": {
      "command": "npx",
      "args": [
        "-y",
        "obsidian-mcp-secure"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ“Š More in Monitoring

Documentation Overview

obsidian-mcp-secure

npm version npm downloads MCP Registry license npm audit CI coverage Smithery

Secure Model Context Protocol server that turns your Obsidian vault into a reliable data source for any MCP-compatible AI client β€” built from scratch with OWASP Top 10 controls and full audit logging.

Listed on the official Anthropic MCP Registry as io.github.dewtech-technologies/obsidian-mcp-secure.


🧭 Positioning β€” this is NOT a plugin for Obsidian

It's the opposite: it's a bridge that lets Claude Desktop (or any MCP client) read and write inside Obsidian safely. Your AI assistant stays where it lives; your vault becomes a structured, auditable datasource it can reach.

Code
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   MCP    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   HTTP   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   FS   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                 β”‚  stdio   β”‚                      β”‚  :27123  β”‚                    β”‚        β”‚             β”‚
β”‚ Claude Desktop  β”‚ ───────▢ β”‚ obsidian-mcp-secure  β”‚ ───────▢ β”‚  Local REST API    β”‚ ─────▢ β”‚  Vault .md  β”‚
β”‚  (AI client)    β”‚          β”‚  (this package)      β”‚          β”‚ (Obsidian plugin)  β”‚        β”‚             β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
Role in the pipelineComponent
Where you talkClaude Desktop (or any MCP client)
Bridge / access controlobsidian-mcp-secure (this package)
Data gateway inside ObsidianLocal REST API plugin (by Adam Coddington)
Your knowledge.md files in your vault

One-liner: Claude is the brain, this MCP is the arm, Obsidian is the memory.

Why another Obsidian + AI integration?

There are plugins that put Claude inside Obsidian. This is the inverse, and it exists because:

  • Your assistant is Claude Desktop β€” that's where the general-purpose conversations happen. Your notes become one of many contexts Claude can reach, alongside web, GitHub, filesystems, etc.
  • Security is a first-class concern β€” deliberate attack surface, no shell access, path traversal blocked, inputs validated with Zod, every call audited.
  • Zero build, zero account β€” npx obsidian-mcp-secure and done. Works on Windows, macOS, Linux the same way.
  • Composability β€” combine this MCP with fetch, filesystem, git, GitHub, etc., and Claude can cross-reference your vault with external sources in a single conversation.

πŸ› οΈ Available Tools

ToolPurpose
read_noteRead a note by path
list_notesList files/folders in the vault or a subdirectory
create_noteCreate a new .md note
edit_noteOverwrite an existing note (previous content goes to the audit log)
delete_noteDelete a note β€” requires confirm: true (Zod rejects otherwise)
search_notesFull-text / tag search using Obsidian's own search engine
find_note_by_nameFind notes by partial name β€” case-insensitive, no exact path needed
list_tagsEnumerate all tags in the vault with usage count; sortable by name or frequency
create_backlinksAdd [[wikilinks]] to a ## Relacionadas section in a note β€” explicit and auditable

πŸ”’ Security β€” OWASP Top 10

ControlImplementation
A01 β€” Broken Access ControlPath traversal blocked (../, ..\\, encoded variants); .md extension enforced
A02 β€” Cryptographic FailuresAPI key read from .env or process env; never hardcoded, never logged
A03 β€” InjectionAll inputs validated with Zod schemas; no eval, no exec, no shell
A04 β€” Insecure Design512 KB max note size; 50-result cap on search; destructive ops require explicit confirm: true
A05 β€” Security MisconfigurationOnly 127.0.0.1 / localhost accepted as host
A09 β€” Logging & MonitoringFull audit log via winston with size-based rotation (5 MB / 10 files)

Every tool call emits an audit line with action, params (sanitized), success, error, and timestamp.


⚑ Installation

Prerequisites

  1. Obsidian Desktop with a vault open
  2. The Local REST API plugin (by Adam Coddington) β€” install from Community Plugins, enable it, and:
    • Turn on "Enable Non-encrypted (HTTP) Server" (simpler than HTTPS self-signed certs)
    • Copy the API Key shown in the plugin settings
  3. Node.js 18+
  4. Claude Desktop (or another MCP-compatible client)

Configure Claude Desktop

Open %APPDATA%\Claude\claude_desktop_config.json on Windows (or ~/Library/Application Support/Claude/claude_desktop_config.json on macOS) and add:

config.json
{
  "mcpServers": {
    "obsidian-secure": {
      "command": "npx",
      "args": ["-y", "obsidian-mcp-secure"],
      "env": {
        "OBSIDIAN_API_KEY": "your-api-key-from-the-plugin",
        "OBSIDIAN_HOST": "http://127.0.0.1",
        "OBSIDIAN_PORT": "27123",
        "LOG_DIR": "C:/path/to/your/logs"
      }
    }
  }
}

Windows tip: if npx fails silently, switch "command": "npx" to "command": "npx.cmd". Some Claude Desktop builds don't resolve bare npx on PATH.

Restart Claude Desktop (tray β†’ Quit, then reopen) and the 9 tools will show up under obsidian-secure.


🀝 Recommended companions

The real power of MCPs is composability. To reproduce the "read my note β†’ fetch a URL β†’ tell me if I'm applying it correctly" workflow, add the official fetch MCP alongside this one:

config.json
{
  "mcpServers": {
    "obsidian-secure": { "...": "as above" },
    "fetch": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-fetch"]
    }
  }
}

Now Claude has both your vault and the live web in a single conversation.


πŸ’¬ Example prompts

With obsidian-secure + fetch enabled:

"Read my note Projeto API Atendimento.md, then fetch https://developers.facebook.com/docs/whatsapp and tell me if my implementation matches the latest best practices."

"Search my vault for the tag #ideia and summarize the three ideas that appear most often. Then create a new note called Ideias recorrentes.md with the summary."

"Read Atomic Habits - Resumo.md, fetch https://jamesclear.com/atomic-habits, and point out where my notes drifted from the original."

Claude will orchestrate the tool calls automatically β€” no manual chaining.


🧩 Comparison with in-Obsidian plugins

If your workflow lives inside Obsidian's sidebar, plugins like obsidian-claude-code are the right fit. This MCP targets a different shape:

Dimensionobsidian-claude-code (in-Obsidian)obsidian-mcp-secure (this)
Where the AI livesSidebar inside ObsidianClaude Desktop (or any MCP client)
Setupgit clone + bun buildnpx obsidian-mcp-secure
ToolsRead/Write/Edit + Bash + Grep + Glob + WebFetch9 purpose-built, Zod-validated tools
Security postureFull shell access to dev machineTight allowlist, audited, OWASP Top 10
DistributionManual clone, requires Bunnpm + official MCP Registry
Composability with other sourcesInside its own sandboxAny MCP-compatible client can mix it with fetch, GitHub, filesystem, etc.
Best forDev who lives in ObsidianProfessional whose main surface is Claude Desktop

Both are valid β€” they occupy different niches.


πŸ”§ Environment variables

VariableRequiredDefaultDescription
OBSIDIAN_API_KEYβœ…β€”API key from the Local REST API plugin
OBSIDIAN_HOSThttp://127.0.0.1Host (only 127.0.0.1 and localhost are accepted)
OBSIDIAN_PORT27123Port of the plugin's HTTP server
LOG_DIR./logsDirectory for the audit log files

πŸ—ΊοΈ Roadmap

βœ… Shipped in v1.2.1

  • Bug fix: find_note_by_name searches full path (folder + filename)
  • Bug fix: list_tags normalizes all API response formats (object, array of strings, array of objects with tagCount/taggedFilesCount)

βœ… Shipped in v1.2.0

  • DXT package for one-click install in Claude Desktop (npm run build:dxt)

βœ… Shipped in v1.1.0

  • find_note_by_name β€” partial, case-insensitive name match across the entire vault
  • create_backlinks β€” connect related notes with [[wikilinks]] (explicit, auditable)
  • list_tags β€” enumerate all tags in the vault with usage count
  • Unit test suite (70 tests β€” utils, handlers, HTTP client) with Vitest
  • CI pipeline on every PR: tests + coverage + npm audit + static security analysis

πŸ”œ Up next

  • Smithery listing
  • Read-only mode flag for shared / multi-user setups

Ideas and PRs welcome β€” see CONTRIBUTING.md.


πŸ“œ License

MIT β€” see LICENSE.

πŸ™ Credits

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Monitoring View all alternatives
  • E
    Enterprise MCP Gateway

    Production-grade MCP Gateway in Go with RBAC, in-flight PII redaction, and audit logging.

    πŸ“Š Monitoring0 views
    Compare vs Enterprise MCP Gateway β†’
  • World Monitor logoWorld Monitor

    Live global intelligence: real-time markets, conflicts, country risk, chokepoints, energy. 39 tools.

    πŸ“Š Monitoring5 views
    Compare vs World Monitor β†’
  • Panos Salt MCP logoPanos Salt MCP

    Multi-tenant MCP platform with OAuth 2.1, Entra SSO, RBAC and audit logging.

    πŸ“Š Monitoring1 views
    Compare vs Panos Salt MCP β†’
  • Ssh MCP logoSsh MCP

    MCP gateway for controlled SSH access with per-client auth, command policies, and audit logging.

    πŸ“Š Monitoring0 views
    Compare vs Ssh MCP β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Obsidian MCP Secure

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "obsidian-mcp-secure": { "command": "npx", "args": ["-y", "obsidian-mcp-secure"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewObsidian MCP Secure AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/obsidian-mcp-secure?style=directory)](https://allmcps.com/mcp/obsidian-mcp-secure)
HTML Embed
<a href="https://allmcps.com/mcp/obsidian-mcp-secure"><img src="https://allmcps.com/api/badge/obsidian-mcp-secure?style=directory" alt="Obsidian MCP Secure on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ“ŠMonitoring
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedSep 7, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
36Quality signal: Fair Β· 36/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ“Š Monitoring β†’Best MCP servers for Monitoring & Observability β†’Alternatives to Obsidian MCP Secure β†’Install in Claude DesktopInstall in CursorInstall in VS Code